peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,831 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,488 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-50477 EXP Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentica… Patch early 9.8 critical 8.1% 2024-10-28
CVE-2019-9623 EXP Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. Patch early 9.8 critical 8.1% 2019-03-07
CVE-2019-7671 EXP Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may a… Patch early 9.0 critical 8.1% 2019-06-05
CVE-2026-1830 EXP The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffici… Patch early 9.8 critical 8.1% 2026-04-09
CVE-2023-1934 EXP The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Pres… Patch early 9.8 critical 8.1% 2023-05-12
CVE-2014-4912 EXP An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. Patch early 9.8 critical 8.1% 2018-03-22
CVE-2018-7316 EXP Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. Patch early 9.8 critical 8.1% 2018-02-22
CVE-2017-16783 EXP In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. Patch early 9.8 critical 8% 2017-11-10
CVE-2019-19245 EXP NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quote… Patch early 9.8 critical 7.9% 2019-12-02
CVE-2023-39115 EXP install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. Patch early 9.8 critical 7.9% 2023-08-16
CVE-2016-6256 EXP SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcelle… Patch early 9.6 critical 7.9% 2017-05-26
CVE-2020-27422 EXP In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link t… Patch early 9.8 critical 7.9% 2020-11-16
CVE-2022-34128 EXP The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. Patch early 9.8 critical 7.8% 2023-04-16
CVE-2004-0285 EXP PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers t… Patch early 9.8 critical 7.8% 2004-11-23
CVE-2024-39930 EXP The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attac… Patch early 9.9 critical 7.7% 2024-07-04
CVE-2017-15990 EXP Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. Patch early 9.8 critical 7.7% 2017-10-31
CVE-2017-16935 EXP Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restri… Patch early 9.8 critical 7.7% 2017-11-24
CVE-2017-17761 EXP An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) u… Patch early 9.8 critical 7.5% 2017-12-19
CVE-2001-1339 EXP Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for re… Patch early 9.8 critical 7.5% 2001-05-24
CVE-2014-2072 EXP Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks Patch early 9.8 critical 7.4% 2020-01-08
CVE-2012-2226 EXP Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute… Patch early 9.8 critical 7.4% 2020-01-09
CVE-2004-0030 EXP PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remot… Patch early 9.8 critical 7.3% 2004-01-20
CVE-2020-6170 EXP An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the H… Patch early 9.8 critical 7.3% 2020-01-08
CVE-2018-9035 EXP CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to… Patch early 9.6 critical 7.3% 2018-04-04
CVE-2014-5087 EXP A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user exe… Patch early 9.8 critical 7.2% 2020-02-07
CVE-2021-21276 EXP Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site… Patch early 9.3 critical 7.2% 2021-02-01
CVE-2017-11502 EXP Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. Patch early 9.8 critical 7.1% 2017-07-20
CVE-2017-15220 EXP Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This… Patch early 9.8 critical 7.1% 2017-10-11
CVE-2008-5784 EXP V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to… Patch early 9.8 critical 7.1% 2008-12-31
CVE-2013-1465 EXP The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP object… Patch early 9.8 critical 7.1% 2013-02-08
← previous page 50 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt